Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AaronCP
Advisor

Changing Mgmt interface on gateway cluster

Good evening,

 

I need to move our DMZ network from its current interface to a new one. Whoever configured the cluster initially put our DMZ network on the Mgmt interface, and I'd like to move it to a separate spare interface so that the Mgmt port can be used for its intended purpose.

 

What is the best way to do this to minimise interruption? My current thinking is to use the Gaia portal to delete the interface from both cluster members, then configure the new interface with the same IPs. Then use the 'Get Interfaces without topology' in SmartConsole to then configure the cluster/VIP/network etc and install policy to the cluster. I've removed the Security Zone assigned to the current Mgmt interface from all rules and replaced with a network object in preparation for the move.

 

Is this the correct approach? Any help would be much appreciated 🙂.

 

Thanks,

 

Aaron.

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

Just to clarify are you talking about the physical Management port or has someone assigned the Mgmt interface role to another port?

From CLISH "show management interface" will show the current allocation.

CCSM R77/R80/ELITE
0 Kudos
AaronCP
Advisor

Hi @Chris_Atkinson 

 

It's the physical Mgmt port of the appliance. I'm not sure which interface has the management role. I can check this later.

0 Kudos
AaronCP
Advisor

Hi @Chris_Atkinson 

 

The Mgmt port has the management interface role assigned to it. Does this complicate matters?

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Not really, just wanted to ensure that we had all the information rather than making assumptions. 

Be sure to have the correct routes in place and where possible make allowances in your policy for the new Mgmt IP addresses / network prior to preserve communication with the SMS.

CCSM R77/R80/ELITE
0 Kudos
just13pro
Collaborator

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events